CVE-2025-25288

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 14, 2025
CWE ID 1333

Summary

CVE-2025-25288 is a vulnerability affecting the `@octokit/plugin-paginate-rest` package, used for paginating responses from the Octokit REST API. Versions prior to 11.4.1 are susceptible to a ReDoS (Recursive Denial of Service) attack. A malicious `link` parameter in the `headers` section of the `request` can be exploited by a specially crafted `octokit` instance, leading to excessive resource consumption and potential denial of service. The vulnerability has been addressed in version 11.4.1, which includes a fix for the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share